Certified Information Privacy Professional CIPPE · Free Practice Question Easy

Question 14

What is true about a company that was exposed to a ransomware attack, but the data that was exposed is encrypted?

  • A

    There was no data breach

  • B

    The company experienced a personal data breach

  • C

    The company must notify the DPA

  • D

    The company must notify the affected customers

Reveal correct answer

Correct answer: B

Explanation

This was a data breach as the hacker was able to access encrypted personal data and a data breach is defined as an unauthorized or accidental disclosure of or access to personal data.

In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.

When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.

In this case, as the data that was exposed was encrypted the breach is unlikely to result n a high risk to the rights and freedoms of natural persons. Therefore neither the DPA nor customers should be notified.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need